Impact
The vulnerability is in the ksmbd SMB server component of the Linux kernel. A malicious SMB client can craft an authentication response with an inflated hash_sz value, causing the ksmbd_alloc_user() function to copy more bytes than the bounded on‑stack buffer allows. This overflow triggers a slab‑out‑of‑bounds read detected by KASAN and results in a kernel panic or crash. The flaw does not provide data disclosure to the attacker beyond the fault, but it can be used to destabilise the kernel, effectively denying service.
Affected Systems
All Linux kernel builds that incorporate the ksmbd SMB server module before the commit that adds hash_sz validation are vulnerable. The patch is present in later kernel releases; any distribution that has not applied the commit is susceptible. No specific vendor version range is listed, so any kernel that includes the legacy ksmbd code path is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote SMB client that can send a forged authentication response to a running ksmbd service; exploitation requires network connectivity to the SMB port and is performed by manipulating a login request that overflows the hash_sz field, leading to a kernel panic or crash.
OpenCVE Enrichment